AUSTRAC reporting

Tipping Off: The Confidentiality Trap Small Firms Don't See Coming

26 September 2026 · 4 min read

Closed confidential file representing controls against tipping off

In brief

Tipping off occurs when a reporting entity tells or implies to a customer or another person that it has formed a suspicion or submitted an SMR. Law firms need restricted access, careful communications, training and audit logs to reduce this risk.

Law firms are built on client relationships and open communication, and that is exactly what makes tipping off a real risk.

What is tipping off?

AUSTRAC describes tipping off as a reporting entity telling a customer or another person, or implying, that it has formed a suspicion or submitted an SMR. The AML/CTF Act restricts disclosure of this information, and breaches carry serious consequences.

How it happens in practice

None of these are malicious, and all of them are risks.

  • A junior asks the client for "more documents because compliance is looking into it".
  • A partner who has known the client for 20 years calls to say "there's a bit of a problem with your file".
  • An email thread about the concern is forwarded to a shared matter inbox the client's representative can see.
  • The client's file shows "SMR pending" to every staff member, including the one who is friends with the client.

What AUSTRAC expects

AUSTRAC said solutions should help reporting entities manage tipping off through:

  • access controls
  • audit logs
  • workflows that limit who can view or share SMR-related information

Practical steps

1. Limit SMR information to the compliance officer and a named backup. 2. Keep SMR records out of the general matter file. 3. Train staff on neutral scripts for asking for extra information. 4. Log who viewed or exported anything related to a suspicion. 5. Decide in advance how you will handle continuing to act, or stopping, while an SMR is open.

How Comply.LM helps

General information only, not legal advice. Get advice on how the tipping-off provisions and legal professional privilege apply to your firm.

  • Today: Comply.LM has role-based access control and an attributed, timestamped decision trail.
  • Coming next: SMR records will sit in a restricted workspace, invisible from the client file. Every view and export will be logged, and staff will be warned before sending client communications on a sensitive matter.

Authoritative sources

This article draws on current AUSTRAC guidance. Always check the source guidance for updates that apply to your circumstances.

Common questions

What is an example of tipping off?

Telling a client that compliance is investigating them, or exposing an “SMR pending” label to unauthorised staff, may reveal or imply that a suspicion exists.

Who should see SMR information?

Access should be limited to authorised people with a genuine need to know, such as the AML/CTF compliance officer and named delegates.